1. https://appdevelopermagazine.com/security
  2. https://appdevelopermagazine.com/salesforce-data-breach-linked-to-tenable-via-salesloft-drift/
9/12/2025 7:05:19 AM
Salesforce data breach linked to Tenable via Salesloft Drift
Cybersecurity,Threats, Artificial intelligence,Malicious cyber campaigns,Salesforce Security,Data Breach,SaaS,Security, Development
/salesforce-data-breach-linked-to-tenable-via-salesloft-drift-app-developer-magazine_o777xcew.jpg
App Developer Magazine

Security

Salesforce data breach linked to Tenable via Salesloft Drift


Friday, September 12, 2025

Richard Harris Richard Harris

A recent investigation into the Salesforce data breach linked to Tenable highlights risks in third-party SaaS integrations and underscores the need for organizations to strengthen access controls and monitor connected apps.

A recent Salesforce data breach involving the Salesloft Drift integration has affected multiple organizations, including cybersecurity company Tenable. The company confirmed that limited customer contact and support case data were exposed but emphasized that no core product data was compromised.

Scope of exposed information

Tenable reported that information accessed included names, email addresses, phone numbers, business regions, and details submitted through support case subject lines and descriptions. The company said core platform and product data were not impacted, according to its investigation and official disclosures. These details reflect Tenable’s own statements about the incident. 

How attackers exploited Salesforce integrations

Investigators have tied the breach to an ongoing cyber campaign targeting organizations that use Salesforce with the Salesloft Drift marketing tool. Reports from outlets like CRN and Cybersecurity News note that attackers leveraged compromised OAuth tokens and credentials to extract sensitive data. Other affected companies reportedly include Palo Alto Networks, Zscaler, Cloudflare, Proofpoint, and CyberArk. 

Tenable’s remediation efforts

Following its discovery of the breach, Tenable says it:

  • Revoked and rotated credentials for Salesforce and related services
  • Disabled and removed the Drift integration from its Salesforce environment
  • Hardened access controls across its SaaS infrastructure
  • Applied threat intelligence from Salesforce and third-party security researchers
  • Deployed continuous monitoring tools to detect further suspicious activity

Tenable stressed that its quick response was meant to reduce the risk of additional exposure.

Salesforce data breach linked to Tenable via Salesloft Drift


Representation of cybersecurity

Salesforce data breach highlights SaaS supply chain risks

The Salesforce–Salesloft Drift breach reflects a growing trend of attackers targeting SaaS ecosystems rather than traditional endpoints. As organizations integrate more third-party apps into platforms like Salesforce, the risk of exposure rises. Experts recommend stronger identity and access management, frequent credential rotation, and strict least-privilege policies.

Industry reactions

CRN reported that security vendors have begun auditing Salesforce integrations in response to the campaign. Salesforce has not released detailed findings about the attack, though third-party researchers have confirmed that stolen tokens and integration misconfigurations were likely factors.

Nick Percoco, chief security officer at cryptocurrency exchange Kraken, told Reuters in related reporting that similar phishing and impersonation schemes remain common. He noted that the challenge of validating legitimate recruiters, partners, or SaaS connectors is growing as attackers refine their methods.

Best practices for organizations

Cybersecurity specialists recommend the following to help mitigate risks:

  1. Audit all third-party integrations to confirm necessity and tighten permissions.
  2. Implement strong identity and access management policies with multi-factor authentication.
  3. Monitor and rotate API keys and OAuth tokens to reduce exposure time.
  4. Use SaaS Security Posture Management (SSPM) solutions for visibility into misconfigurations.
  5. Run tabletop exercises simulating SaaS-based supply chain breaches to improve readiness.

Transparency and disclosure

Tenable’s approach reflects growing industry pressure for transparency. While no core data or platform systems were compromised, the breach illustrates how third-party connections can create unintended entry points for attackers.

As supply chain attacks become more common, customers and vendors are placing a higher priority on full disclosure of security incidents to maintain trust. Analysts see this as part of a broader shift toward proactive security communication.

The Salesforce data breach tied to Tenable and other vendors underscores the complexity of securing interconnected SaaS environments. While Tenable’s investigation and actions appear to have limited further risk, experts emphasize the importance of reviewing integrations, implementing zero-trust principles, and strengthening response plans.

Organizations relying on cloud-based tools should view this event as a reminder to adopt continuous monitoring, limit access permissions, and proactively address vulnerabilities before they are exploited.






Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Featured Stories


FTC AI accuracy policy puts chatbot trust under review
FTC AI accuracy policy puts chatbot trust under review Tuesday, July 21, 2026


Human-Made Video Ads Outperform AI-Generated Creativity
Human-Made Video Ads Outperform AI-Generated Creativity Monday, July 20, 2026


SpaceX accelerates AI push with new hires
SpaceX accelerates AI push with new hires Monday, July 20, 2026




NearLens: Smart Glasses Privacy Taken Seriously
NearLens: Smart Glasses Privacy Taken Seriously Wednesday, July 15, 2026


Agentic Commerce Grows Cequence Unveils AI-Era Bot Defense
Agentic Commerce Grows Cequence Unveils AI-Era Bot Defense Wednesday, July 15, 2026


Nearly all developers use AI but few secure the code it generates
Nearly all developers use AI but few secure the code it generates Monday, July 13, 2026


Enviromates new browser launches
Enviromates new browser launches Monday, July 6, 2026


AI Executive Order aims to balance security and innovation
AI Executive Order aims to balance security and innovation Monday, June 29, 2026


Top manufacturing trends for 2026
Top manufacturing trends for 2026 Tuesday, June 23, 2026


API scoring tool shows if your API is ready for AI
API scoring tool shows if your API is ready for AI Monday, June 22, 2026


Get More App News